15
I think this may also be a problem with malicious clients. Currently the user enters the username and password via the client's login dialog. It's an effective way to collect credentials.
I think this may also be a problem with malicious clients. Currently the user enters the username and password via the client's login dialog. It's an effective way to collect credentials.
Yes you’re right, implementing OAuth or similar would fix this
I really hope we get OAuth support soon. Other fediverse apps (ie Mastodon) already implement this so that should help roadmap a path forward for Lemmy.
Good tip. Wrote this up as a bug against my project. It's not a full-proof solution (malicious attacker could have setup a lemmy instance modified to save off credentials) but it's probably a good idea.
thanks a lot for this
A place for Lemmy builders to chat about building apps, clients, tools and bots for the Lemmy platform.
On-Topic:
Off-Topic: